How to answer the ISO 27001 Annex A control?
Answering an ISO 27001 Annex A control means explaining how that control relates to your organisation, why you need it, how you have applied it, who owns it and what evidence proves that it works.
A good answer goes beyond selecting yes or no. It should connect the control with your Information Security Management System, risk assessment, legal duties, contracts, customer expectations and normal business processes.
ISO/IEC 27001:2022 contains 93 Annex A controls grouped under organisational, people, physical and technological headings. Annex A provides a reference set rather than a fixed checklist that every organisation must copy. Your organisation must determine the controls it needs through risk treatment, compare its choices with Annex A and record the final position in the Statement of Applicability.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps organisations manage risks, controls, policies, actions, owners, evidence and audit preparation from one central location.
Start with the question behind each control
Every Annex A control exists to support a security objective. Before writing an answer, ask what the control aims to protect and why that protection matters to your business.
For example, an access control measure aims to prevent people from reaching information or systems that they do not need. A backup measure supports recovery when information becomes lost, corrupted or unavailable. A supplier security measure helps the business control risks created by external providers.
Your answer should explain the business reason for the control. Avoid copying the control title into the answer and treating that as sufficient.
A useful answer should cover six points:
- Does the control apply?
- Why does it apply or not apply?
- How does the organisation meet it?
- Who owns the control?
- What evidence supports the answer?
- Are any gaps or actions still open?
These points create a clear audit trail. They also help managers understand whether the control operates properly rather than merely appearing in a document.
What is ISO 27001 Certification?
ISO 27001 certification provides independent confirmation that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.
An Information Security Management System, often shortened to ISMS, gives the organisation a structured way to manage information security. It connects leadership, risk assessment, risk treatment, policies, objectives, staff awareness, suppliers, technology, internal audit, management review and continual improvement.
ISO describes ISO/IEC 27001 as the best-known standard for information security management systems. It allows an organisation to apply a risk management process that matches its scale and needs.
Certification does not prove that a business will never face a security incident. It shows that the organisation has created a controlled and independently assessed approach to protecting information.
Annex A answers form an important part of that approach. They help the organisation explain how individual controls address relevant risks and obligations.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001, the international requirements standard for an ISMS.
The standard helps organisations protect confidentiality, integrity and availability through risk management. Confidentiality means information only reaches authorised people and systems. Integrity means information remains accurate and reliable. Availability means authorised users can access information and services when needed.
ISO 27001 does not treat information security as an IT-only responsibility. It promotes a joined approach across people, policies, technology, suppliers, business processes and management controls.
When you answer an Annex A control, you should therefore consider more than technical settings. Ask how staff follow the control, how managers review it, how suppliers affect it and how the organisation records evidence.
Answer applicability before describing implementation
The first decision asks whether the control applies to the organisation.
A control may apply because of:
A risk identified in the risk assessment
A legal or regulatory duty
A customer or contract requirement
An interested party’s expectation
A business continuity need
An internal policy decision
A recognised security practice needed within the ISMS scope
Do not select applicable simply because Annex A contains the control. Equally, do not exclude a control because implementation feels difficult.
Your reasoning should reflect the organisation’s real environment. Consider its services, systems, data, staff, suppliers, locations and customers.
A control may also apply even when a supplier performs the activity. For example, a cloud provider may manage physical data centre security, but your organisation still needs supplier assurance and contractual controls. The responsibility changes, but the risk does not disappear.
Write a strong reason for inclusion
A clear inclusion answer explains why the organisation needs the control.
Consider this weak example:
“The control applies because ISO 27001 requires it.”
That answer provides little value because ISO 27001 does not require automatic application of every Annex A control.
A stronger answer might say:
“The control applies because employees and approved suppliers access confidential customer information through cloud services. The organisation needs controlled user access to reduce unauthorised disclosure and support contractual security requirements.”
This wording connects the control with information, users, systems, risk and customer obligations.
Another example for backup could say:
“The control applies because loss or corruption of operational and customer information could interrupt service delivery. Backup and recovery arrangements support availability requirements and agreed recovery objectives.”
The best answers explain the organisation’s actual reason in plain business language.
Explain exclusions carefully
A control may not apply when the organisation has no relevant risk, activity, asset or environment within the ISMS scope.
For example, a measure relating to secure development may not apply if the organisation does not create software and does not outsource software development within the scope.
A strong exclusion might say:
“The control does not apply because the organisation does not develop or commission software within the ISMS scope. It uses commercially available cloud applications that undergo supplier security review.”
This answer explains the business position and identifies a related control.
Avoid vague exclusions such as:
“Not relevant.”
“We do not need this.”
“Handled by IT.”
“Managed by a supplier.”
Each of these statements leaves unanswered questions. An auditor may ask why the control has no relevance, how IT manages it or how the organisation assures the supplier.
The ISO risk treatment process requires the organisation to justify excluded Annex A controls. A clear exclusion shows that the business considered the control rather than overlooking it.
Describe what the organisation actually does
After confirming applicability, explain how the organisation meets the control.
Focus on operating practice. Describe the process, responsibilities, tools, checks and records that support the control.
For access rights, an answer may explain that managers approve access according to role, IT creates named accounts, system owners review permissions at planned intervals and HR triggers removal when staff leave.
For vulnerability management, the answer may explain how the organisation receives vulnerability information, assesses relevance, assigns actions, applies fixes and records exceptions.
For staff awareness, describe onboarding, periodic learning, phishing guidance, policy communication and reporting routes.
Avoid writing an answer that only names a policy. A policy provides direction, but the auditor also needs evidence that people follow the process.
Use a repeatable answer structure
A consistent template makes all 93 controls easier to manage.
A practical structure could use the following fields:
Control reference
Record the Annex A number and control name.
Applicability
State whether the control applies.
Reason
Explain the risk, legal duty, contract, customer need or business requirement behind the decision.
Implementation
Describe how the organisation carries out the control.
Ownership
Name the role responsible for maintaining the control.
Evidence
List the documents, records, reports or system information that prove operation.
Status
Record whether the control operates fully, partly or remains planned.
Actions
Record gaps, owners and target dates.
This format supports consistency across the Statement of Applicability, risk treatment plan, policies and audit evidence.
The Statement of Applicability holds the formal answer
The Statement of Applicability, often called the SoA, records the controls the organisation has determined are necessary, reasons for inclusion, implementation status and reasons for excluding Annex A controls.
The SoA acts as a bridge between risk assessment and control operation. It shows how the organisation moved from identified risk to selected security measures.
Your detailed control answers may sit inside the SoA or in a connected control register. Either approach can work when the information remains clear, current and easy to trace.
The SoA should agree with the risk register. If the risk assessment identifies a major supplier risk, the SoA should show suitable supplier controls. If it identifies account compromise risk, the control set should address identity, access and authentication.
Contradictions create audit questions. The scope, risk assessment, treatment plan, SoA, policies and evidence should tell one consistent story.
Connect each answer to risk treatment
Risk assessment identifies what could go wrong. Risk treatment decides what the organisation will do about it.
The organisation may reduce, avoid, transfer or accept a risk. Annex A controls often support risk reduction.
Suppose the risk register identifies unauthorised access to customer data. The organisation may select controls covering access rights, authentication, logging, monitoring, staff responsibilities and supplier access.
The control answers should show how those measures work together.
Do not force a one-to-one relationship between every risk and control. One risk may require several controls, while one control may address several risks.
The goal involves traceability rather than artificial simplicity.
Answer organisational controls in business language
Organisational controls cover governance, policies, assets, suppliers, incidents, continuity, legal duties and operational procedures.
A strong answer should explain the process and decision-making structure.
For information security policies, describe who approves them, how staff access them, how often the organisation reviews them and how it records changes.
For supplier security, explain how the business assesses suppliers before approval, adds security requirements to agreements, reviews service performance and removes access when the relationship ends.
For incident management, describe reporting routes, triage, escalation, communication, evidence preservation, learning and corrective action.
For threat intelligence, explain which reliable sources the organisation reviews, who evaluates relevant information and how findings lead to action.
Keep the answer proportionate. A small organisation may use concise processes, named managers and support from an external provider. It does not need to copy the structure of a multinational company.
Answer people controls with evidence of behaviour
People controls address screening, employment responsibilities, awareness, confidentiality, remote working and event reporting.
A weak answer might state:
“All employees receive security training.”
A stronger answer explains when training happens, who completes it, which topics it covers, how the business tracks completion and how it responds when someone misses the requirement.
For confidentiality agreements, explain which roles sign them, when the business obtains signatures and where records sit.
For leaver responsibilities, describe account removal, equipment return, ongoing confidentiality and transfer of business information.
For remote working, explain approved devices, access controls, physical privacy, information handling and incident reporting.
Evidence may include training records, signed agreements, onboarding checklists, leaver records, policy acknowledgements and reported security events.
Answer physical controls according to the real environment
Physical controls protect offices, secure areas, devices, equipment, storage media, cabling and utilities.
Remote businesses should not dismiss this area automatically. Staff may work from home, travel with laptops or hold paper records. Cloud providers may also manage physical infrastructure on the organisation’s behalf.
For physical entry, explain how the business controls access to offices or restricted rooms. Evidence may include access records, visitor logs, key registers or periodic checks.
For equipment away from business premises, describe how staff protect devices during travel and home working.
For secure disposal, explain how the organisation removes information from retired devices and which records it keeps.
Where a supplier manages a physical measure, describe how the organisation obtains assurance through contracts, certifications, reports or review activity.
Answer technological controls through process and proof
Technological controls cover endpoint security, authentication, malware, vulnerabilities, configuration, backup, logging, networks, cryptography, development and change management.
These answers often need both a management explanation and technical evidence.
For malware protection, describe the protection method, management responsibility, monitoring and response to alerts.
For backup, explain what the business backs up, how often it runs the process, how it protects backups and how it tests recovery.
For logging, identify important systems, recorded events, retention arrangements, access controls and review responsibilities.
For vulnerability management, describe information sources, scanning, risk evaluation, remediation targets and exception approval.
For secure authentication, explain password or passkey requirements, multi-factor authentication, administrator protection and recovery controls.
Screenshots may help, but they should not form the only evidence. Reports, configuration records, tickets, logs and review notes often provide stronger continuing proof.
Avoid relying on policy text alone
A policy tells people what should happen. It does not always prove that the organisation follows it.
For example, an access policy may state that managers review permissions every six months. The evidence should show completed reviews and any access removed as a result.
A backup policy may require regular recovery testing. The organisation should keep test records and any resulting corrective actions.
An incident policy may require staff to report concerns. Incident logs and awareness records help show that the process works.
Auditors often test the gap between written expectation and actual operation. Strong Annex A answers recognise that distinction.
Choose evidence that directly supports the answer
Evidence should prove the claims made in the control response.
Useful evidence may include:
Approved policies
Risk records
Meeting minutes
Access reviews
System configurations
Supplier assessments
Contracts
Training records
Incident logs
Backup reports
Recovery test results
Vulnerability reports
Change tickets
Monitoring alerts
Internal audit findings
Corrective action records
Do not attach unrelated documents simply to make the evidence list look larger. Relevant, current records provide more value than a large unstructured folder.
Control owners should know where evidence sits and how often they update it.
Record a realistic implementation status
Your answer should distinguish between a control that operates and one that the organisation plans to implement.
Do not mark a control fully implemented because a policy has received approval when the practical process has not started.
A useful status model may include:
Implemented
Partly implemented
Planned
Not applicable
Under review
For partly implemented controls, explain what works and what remains open.
For example:
“The organisation uses multi-factor authentication for email and cloud storage. The finance application does not currently support the chosen authentication method. The service owner has recorded a supplier action and target review date.”
Honest status reporting supports better planning and reduces audit surprises.
Assign the control to a role
Every applicable control should have an owner.
The owner maintains oversight, reviews evidence, raises gaps and ensures that the process continues. They may delegate individual tasks, but they remain accountable for the control.
Use roles rather than personal names where possible. Examples include:
Information Security Manager
IT Manager
Human Resources Manager
Facilities Manager
Operations Director
Service Owner
Supplier Manager
Development Lead
Named roles make the SoA easier to maintain when staff change.
Small organisations may assign several controls to one person. That can work when senior management provides support and the responsibilities remain realistic.
Review answers after business change
An Annex A response can become outdated when the business changes.
Review controls after:
Adding a major supplier
Launching a service
Changing cloud platforms
Opening or closing a location
Changing remote working arrangements
Winning a significant contract
Experiencing an incident
Finding a major vulnerability
Changing legal obligations
Completing an internal audit
The organisation should also conduct planned reviews. A control that worked last year may no longer match current systems or risks.
The ISO 27001 approach supports continual improvement and scaling as organisational needs evolve.
Who needs iso 27001 certification
ISO 27001 certification can benefit any organisation that handles important information and needs to demonstrate structured security management.
Technology providers, software businesses, managed service providers, professional firms, charities, manufacturers, healthcare suppliers, finance-related organisations and public sector contractors may all gain value.
Customers often request ISO 27001 during supplier assurance. They want confidence that a provider manages security across staff, technology, suppliers, premises and business processes.
Tender requirements, investor expectations, insurance discussions, board governance and international growth may also create a need.
The standard suits organisations of different scales because the risk management process can adapt to their needs.
ISO 27001 Certification Levels
ISO 27001 does not award bronze, silver, gold or other achievement bands.
An organisation either holds certification for its stated ISMS scope or it does not. The certificate should identify the organisation, standard, scope and certification body.
Businesses may still move through preparation stages. These may include readiness assessment, scope definition, risk assessment, control selection, implementation, internal audit, management review and external audit.
Security maturity can improve after certification through stronger monitoring, clearer evidence, wider scope, improved automation and better management reporting.
Continual improvement describes that progress. It does not create formal certification bands.
How the Certification Works
The organisation begins by understanding its context and defining the ISMS scope. It identifies relevant services, systems, information, people, suppliers, locations, legal duties and interested parties.
Next, it completes risk assessment and risk treatment. The organisation decides which controls it needs and compares those decisions with Annex A.
It then records the control position in the Statement of Applicability and puts the selected measures into operation.
The business gathers evidence, completes internal audit and holds management review. These activities help identify gaps before the certification assessment.
An external certification body normally conducts a Stage 1 review followed by a Stage 2 assessment. Stage 1 focuses on readiness and core documented information. Stage 2 examines implementation and effectiveness.
After successful certification, surveillance activity checks whether the ISMS remains active and suitable during the certification cycle.
How auditors test your control answers
Auditors do not normally review every control in the same depth during one assessment. They use sampling to test whether the system operates effectively.
An auditor may:
Interview the control owner
Review the SoA justification
Trace the control to a risk
Check a related policy
Inspect operational evidence
Review recent records
Test whether staff understand the process
Compare practice with the written answer
Follow up on open actions
An answer should therefore remain easy to explain. Avoid vague or overly technical wording that the control owner cannot defend.
The strongest response lets the auditor follow a clear path from risk to control, from control to process and from process to evidence.
Common mistakes when answering controls
One frequent mistake involves answering every control with a simple yes. That provides no explanation or proof.
Another involves copying generic responses that do not match the organisation.
Some businesses exclude controls because suppliers manage the activity. The organisation still needs to explain how it oversees the supplier.
Others mark controls implemented when work remains incomplete.
Weak evidence creates another problem. A policy without operational records may not prove effectiveness.
Poor ownership also causes gaps. Controls can stop operating when responsibility remains unclear.
Finally, businesses often prepare answers for audit day and forget them afterwards. The control register and SoA should remain living management records.
Current cyber risk makes strong answers worthwhile
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a breach or attack during the previous 12 months. This represented around 612,000 UK businesses.
Medium and large businesses reported higher levels than micro and small businesses, although the Government noted that smaller organisations may have weaker detection and reporting.
These findings show why Annex A controls need meaningful operation. A polished answer cannot protect information unless the organisation follows the process and reviews the evidence.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can seek support from information security consultancies, compliance advisers, managed service providers, internal audit specialists and platform-led providers.
UK Cyber Compliance supports ISO 27001 through an automated and AI-driven platform. It helps organisations manage compliance tasks, risk information and audit-ready documentation with improved visibility.
A capable provider should help the organisation understand scope, risk assessment, treatment, Annex A, the Statement of Applicability, internal audit and management review.
Good support should leave the organisation able to operate its own ISMS. The adviser should explain decisions clearly and help control owners understand their responsibilities.
Avoid a temporary audit-only approach. Certification provides more lasting value when processes form part of everyday business activity.
How UK Cyber Compliance helps answer Annex A controls
Managing 93 controls through disconnected files can create unnecessary administration. Evidence can become outdated, actions may lose ownership and managers may struggle to see progress.
UK Cyber Compliance brings controls, risks, policies, evidence and actions into one platform. AI-powered automation can help streamline compliance work, reduce repeated effort and provide clearer insight into certification progress.
The organisation still makes the important decisions. Leaders define the scope, approve risk treatment and confirm that controls meet business needs.
The platform supports those decisions by organising information, highlighting gaps and keeping audit records accessible.
A practical Annex A answer template
Use this structure for each control:
Control reference: Record the Annex A number and title.
Applicability: State yes or no.
Reason: Explain the linked risk, legal duty, contract, customer need or business requirement.
Implementation: Describe the process in operation.
Owner: Name the responsible business role.
Evidence: List specific current records.
Status: Record the real level of implementation.
Actions: Add gaps, responsible owners and target dates.
Review: Record when the organisation last checked the answer and when it will review it again.
This approach gives control owners a clear framework and creates a consistent record for internal and external audit.
Turn each answer into useful security management
A strong Annex A answer does more than satisfy an auditor. It helps the organisation understand why a control matters, who owns it and whether it works.
Start with risk. Decide whether the control applies. Explain the reason clearly. Describe the real process. Name the owner. Attach relevant evidence. Record gaps honestly and review the answer after change.
The Statement of Applicability should bring these decisions together and show how the organisation’s control environment supports its ISMS.
UK Cyber Compliance provides an automated and AI-driven platform that helps organisations manage this process more efficiently. By connecting risks, controls, evidence, policies and actions, the platform supports a clearer route to ISO 27001 certification and ongoing information security improvement.
For a UK business, the best Annex A answer remains clear, specific, evidence-based and honest. It should describe what the organisation genuinely does rather than what it hopes to do before the next audit.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts: Your ISO 27001 Questions Answered, Get ISO 27001 Certified
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

